Step 5: Configure Group Policy Settings for Automatic Updates

 

Applies To: Windows Server 2012 R2, Windows Server 2012

In an Active Directory environment, you can use Group Policy to define how computers and users (referred to in this document as WSUS clients) can interact with Windows Updates to obtain automatic updates from Windows Server Update Services (WSUS).

This topic contains two main sections:

Group Policy settings for WSUS client updates, which provides prescriptive guidance and behavioral details about the Windows Update and Maintenance Scheduler settings of Group Policy that control how WSUS clients can interact with Windows Update to obtain automatic updates.

Supplemental information has the following sections: For administrators who are not already familiar with Group Policy, the first section provides an overview about the general use of Group Policy. The second section contains a table that summarizes the differences in the default verses manual installation of WSUS in current and previous version of WSUS. The third section contains a list and definitions about terminology used in this guide.

  • Accessing the Windows Update settings in Group Policy, which provides general guidance about using Group Policy Management Editor, and information about accessing the Update Services policy extensions and Maintenance Scheduler settings in Group Policy.

  • Changes to WSUS relevant to this guide: for administrators familiar with WSUS 3.2 and previous versions, this section gives a brief summary of key differences between the current and past version of WSUS relevant to this guide.

  • Terms and Definitions: definitions for various terms pertaining to WSUS and update services that are used in this guide.

Group Policy settings for WSUS client updates

This section provides information about three extensions of Group Policy. In these extensions you will find the settings that you can use to configure how WSUS clients can interact with Windows Update to receive automatic updates.

Note

This topic assumes that you already use and are familiar with Group Policy. If you are not familiar with Group Policy, it is advised that you review the information in the Supplemental information section of this document before attempting to configure policy settings for WSUS.

Computer Configuration > Windows Update policy settings

This section provides details about the following computer-based policy settings:

In the GPME, Windows Update policies for computer-based configuration are located in the path: PolicyName > Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update.

Note

By default, these settings are not configured.

Allow Automatic Updates immediate installation

Specifies whether Automatic Updates will automatically install updates that do not interrupt Windows services or restart Windows.

Supported on:

Excluding:

Windows operating systems that are still within their Microsoft Products Support Lifecycle.

null

Note

If the “Configure Automatic Updates” policy setting is set to Disabled, this policy has no effect.

Policy setting state

Behavior

Not Configured

Specifies that updates are not immediately installed. Local administrators can change this setting by using the Local Group Policy Editor.

Enabled

Specifies that Automatic Updates immediately installs updates after they are downloaded and ready to install.

Disabled

Specifies that updates are not immediately installed.

Options: There are no options for this setting.

Allow non-administrators to receive update notifications

Specifies whether non-administrative users will receive update notifications based on the Configure Automatic Updates policy setting.

Supported on:

Excluding:

Windows operating systems that are still within their Microsoft Products Support Lifecycle.

See details in the table below.

Note

If the “Configure Automatic Updates” policy setting is disabled or is not configured, this policy setting has no effect.

Important

Starting in Windows 8 and Windows RT, this policy setting is enabled by default. In all prior versions of Windows, it is disabled by default.

Note

Policy setting state

Options: There are no options for this setting.

Allow signed updates from an intranet Microsoft update service location

Specifies whether Automatic Updates accepts updates that are signed by entities other than Microsoft when the update is found on an intranet Microsoft update service location.

Supported on:

Excluding:

Windows operating systems that are still within their Microsoft Products Support Lifecycle.

Windows RT

Note

Updates from a service other than an intranet Microsoft update service must always be signed by Microsoft, and they are not affected by this policy setting.

Note

This policy is not supported on Windows RT. Enabling this policy will not have any effect on computers running Windows RT.

Options: There are no options for this setting.

Policy setting state

Behavior

Not Configured

Specifies that updates from an intranet Microsoft update service location must be signed by Microsoft.

Enabled

Specifies that Automatic Updates accepts updates received through an intranet Microsoft update service location if they are signed by a certificate found in the local computer’s "Trusted Publishers" certificate store.

Disabled

Specifies that updates from an intranet Microsoft update service location must be signed by Microsoft.

Options: There are no options for this setting.

Always automatically restart at the scheduled time

Specifies whether a restart timer will always begin immediately after Windows Update installs important updates, instead of first notifying users on the sign-in screen for at least two days.

Supported on:

Excluding:

Windows operating systems that are still within their Microsoft Products Support Lifecycle.

null

Note

If the "No auto-restart with logged on users for scheduled automatic updates installations" policy setting is enabled, this policy has no effect.

Policy setting state

Behavior

Not Configured

Specifies that Windows Update will not alter the computer’s restart behavior.

Enabled

Specifies that a restart timer will always begin immediately after Windows Update installs important updates, instead of first notifying users on the sign-in screen for at least two days.

The restart timer can be configured to start with any value from 15 to 180 minutes. When the timer runs out, the restart will proceed even if the computer has signed-in users.

Disabled

Specifies that Windows Update will not alter the computer’s restart behavior.

Options: If this setting is enabled, you can specify the amount of time that will elapse after updates are installed before a forced computer restart occurs.

Automatic Updates detection frequency

Specifies the hours that Windows will use to determine how long to wait before checking for available updates. The exact wait time is determined by using the hours specified here minus zero to twenty percent of the hours specified. For example, if this policy is used to specify a 20 hour detection frequency, all clients to which this policy is applied will check for updates anywhere between 16 and 20 hours.

Supported on:

Excluding:

Windows operating systems that are still within their Microsoft Products Support Lifecycle.

Windows RT

Note

The “Specify intranet Microsoft update service location” setting must be enabled for this policy to have effect. If “Configure Automatic Updates” policy setting is disabled, this policy has no effect.

Note

This policy is not supported on Windows RT. Enabling this policy will not have any effect on computers running Windows RT.

Policy setting state

Behavior

Not Configured

Specifies that Windows will check for available updates at the default interval of 22 hours.

Enabled

Specifies that Windows will check for available updates at the specified interval.

Disabled

Specifies that Windows will check for available updates at the default interval of 22 hours.

Options: If this setting is enabled, you can specify the time interval (in hours) that Windows Update waits before checking for updates.

Configure Automatic Updates

Specifies specify whether automatic updates are enabled on this computer.

Supported on:

Excluding:

Windows operating systems that are still within their Microsoft Products Support Lifecycle.

Windows RT

If enabled, you must select one of the four options provided in this Group Policy setting.

To use this setting, select Enabled, and then in Options under Configure automatic updating, select one of the options (2, 3, 4, or 5).

Note

Policy setting state